İçeriğe atla
Noroxi

CWE-384 · 417 kayıt

Session Fixation

Bu sınıftaki CVE’ler

417 kayıt

  • CVE-2018-11714
    59Planlayın

    An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0

    KritikCVSS 9,8Kavram kanıtıEPSS %68

    tp-link · tl-wr840n firmware4 Haz 2018

  • CVE-2018-18925
    48Planlayın

    Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery

    KritikCVSS 9,8Kavram kanıtıEPSS %31

    gogs · gogs4 Kas 2018

  • CVE-2017-12965
    44Planlayın

    Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter.

    KritikCVSS 9,8Kavram kanıtıEPSS %16

    apache2triad · apache2triad23 Ağu 2017

  • CVE-2025-52689
    43Planlayın

    Weak Session ID Check in the OmniAccess Stellar Web Management Interface

    KritikCVSS 9,8Kavram kanıtıEPSS %14

    alcatel-lucent · omniaccess stellar products16 Tem 2025

  • CVE-2019-10008
    41Planlayın

    Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically co

    YüksekCVSS 8,8Kavram kanıtıEPSS %19

    zohocorp · servicedesk plus24 Nis 2019

  • CVE-2021-36394
    41Planlayın

    In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.

    KritikCVSS 9,8Kavram kanıtıEPSS %7

    moodle · moodle6 Mar 2023

  • CVE-2015-1820
    40Planlayın

    REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie i

    KritikCVSS 9,8İstismar yokEPSS %4

    rest-client project · rest-client9 Ağu 2017

  • CVE-2019-18418
    40Planlayın

    clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no se

    KritikCVSS 9,8Kavram kanıtıEPSS %4

    clonos · clonos24 Eki 2019

  • CVE-2019-5523
    40Planlayın

    VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerability in the Tenant and

    KritikCVSS 9,8İstismar yokEPSS %3

    vmware · vcloud director1 Nis 2019

  • CVE-2018-18926
    40Planlayın

    Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs.

    KritikCVSS 9,8İstismar yokEPSS %3

    gitea · gitea4 Kas 2018

  • CVE-2015-1174
    40Planlayın

    Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack we

    KritikCVSS 9,8İstismar yokEPSS %3

    unit4 · teta web2 Ağu 2017

  • CVE-2016-9125
    40Planlayın

    Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by

    KritikCVSS 9,8İstismar yokEPSS %3

    revive-adserver · revive adserver27 Mar 2017

  • CVE-2020-5543
    40Planlayın

    TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier does not proper

    KritikCVSS 9,8İstismar yokEPSS %2

    mitsubishielectric · iu1-1m20-d firmware15 Mar 2020

  • CVE-2022-38054
    40Planlayın

    In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.

    KritikCVSS 9,8İstismar yokEPSS %2

    apache · airflow2 Eyl 2022

  • CVE-2017-12868
    40Planlayın

    The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows atta

    KritikCVSS 9,8İstismar yokEPSS %2

    simplesamlphp · simplesamlphp1 Eyl 2017

  • CVE-2023-31498
    40Planlayın

    A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary code

    KritikCVSS 9,8İstismar yokEPSS %2

    phpgurukul · hospital management system11 May 2023

  • CVE-2018-6959
    40Planlayın

    VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs.

    KritikCVSS 9,8İstismar yokEPSS %2

    vmware · vrealize automation13 Nis 2018

  • CVE-2019-10158
    40Planlayın

    A flaw was found in Infinispan through version 9.4.14.Final.

    KritikCVSS 9,8İstismar yokEPSS %2

    infinispan · infinispan2 Oca 2020

  • CVE-2016-10405
    40Planlayın

    Session fixation vulnerability in D-Link DIR-600L routers (rev.

    KritikCVSS 9,8İstismar yokEPSS %2

    d-link · dir-600l firmware7 Eyl 2017

  • CVE-2020-11729
    40Planlayın

    An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60.

    KritikCVSS 9,8İstismar yokEPSS %2

    davical · andrew\'s web libraries15 Nis 2020

  • CVE-2025-28242
    40Planlayın

    Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.

    KritikCVSS 9,8Kavram kanıtıEPSS %2

    18 Nis 2025

  • CVE-2021-20151
    40Planlayın

    Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device.

    KritikCVSS 10,0İstismar yokEPSS %2

    trendnet · tew-827dru firmware30 Ara 2021

  • CVE-2017-12873
    39İzleyin

    SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified oth

    KritikCVSS 9,8İstismar yokEPSS %2

    simplesamlphp · simplesamlphp1 Eyl 2017

  • CVE-2023-41012
    39İzleyin

    An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code

    KritikCVSS 9,8İstismar yokEPSS %2

    chinamobile · intelligent home gateway firmware5 Eyl 2023

  • CVE-2021-39290
    39İzleyin

    Certain NetModule devices allow Limited Session Fixation via PHPSESSID.

    KritikCVSS 9,8İstismar yokEPSS %2

    netmodule · netmodule router software23 Ağu 2021

Tüm zafiyet sınıfları